| Document | Information Security Policy |
| Document type | Regulatory framework |
| Classification | Public |
| Entity | AIR FLOWS DATA PLATFORM, S.L. |
| Purpose | Establish the security policy for information systems |
| Version | 1.1 · Approved by the Security Committee on 24/06/2026 (minutes No. 002) |
1. Introduction
AIR FLOWS DATA PLATFORM, S.L., hereinafter AIRFLOWS, depends on information systems to achieve its objectives. These systems must be managed diligently, taking appropriate risk-based measures to protect them against accidental or deliberate damage that may affect the authenticity, traceability, integrity or confidentiality of the information processed, or the availability of the services provided.
The ultimate goal of information security is to ensure that the entity can meet its objectives, carry out its functions and deliver the services for which it was established, preserving the quality of information and the continued provision of services: acting in advance, supervising daily activity and reacting promptly to incidents.
ICT systems must be protected against rapidly evolving threats with the potential to affect the confidentiality, integrity, availability, intended use and value of information and services. Defending against these threats requires a strategy that adapts to changing environmental conditions. This means applying the minimum security measures required by the National Security Framework (ENS), continuously monitoring service levels, tracking and analysing reported vulnerabilities, and preparing an effective incident response.
AIRFLOWS must ensure that ICT security is an integral part of every stage of the system lifecycle, from conception to decommissioning, including development or procurement decisions and operational activities. Security requirements and funding needs must be identifiable and included in planning, requests for proposals and tender documents.
2. Scope
This policy applies to all AIRFLOWS information systems, to the people who make up the organization, and to AIRFLOWS service providers and ICT solution suppliers.
Information system classified as HIGH category under Royal Decree 311/2022.
3. Mission and objectives
At AIRFLOWS we define ourselves as a technology company specialized in the intelligent orchestration of operations through AI, developing a product made available to customers as SaaS and through various partners.
The security objectives that AIRFLOWS seeks to guarantee with this Policy are:
- Guarantee the confidentiality, integrity and authenticity of information and continuity in the provision of services.
- Implement risk-based security measures.
- Train and raise awareness among AIRFLOWS members regarding information security.
- Implement measures enabling access traceability and uphold the principle of least privilege, reinforcing users’ duty of confidentiality.
- Deploy and control physical security, keeping information assets in secure areas protected by access controls.
- Establish security in communications management, ensuring information transmitted over networks is adequately protected.
- Control the acquisition, development and maintenance of systems throughout their lifecycle, ensuring security by default.
- Control compliance with security measures in service provision and in the addition of new system components.
- Manage security incidents for proper detection, containment, mitigation and resolution, adopting measures to prevent recurrence.
- Protect personal information, adopting technical and organizational measures in accordance with data protection legislation.
- Continuously monitor the security management system, improving and correcting detected inefficiencies.
4. Guiding principles
- Strategic scope: information security must have the commitment and support of all levels of the entity and be coherently coordinated and integrated with other strategic initiatives.
- Comprehensive security: security is understood as an integral process made up of all technical, human, material and organizational elements, avoiding one-off actions or ad-hoc treatment. It must be considered part of routine operations and applied from the initial design of ICT systems.
- Risk-based management: security management based on identified risks maintains a controlled environment; measures shall be proportionate to the risk they address and must be justified, also taking into account personal data processing risks.
- Prevention, detection, response and preservation: with preventive actions that minimise vulnerabilities and, when threats materialise, an agile response that restores information or services, guaranteeing secure preservation of information.
- Lines of defence: the security strategy is designed and implemented in layers.
- Continuous monitoring and periodic reassessment: means of detecting and responding to anomalous behaviour are implemented, along with continuous evaluation of asset security status and a continuous improvement process to review and update measures.
- Security by default and by design: systems must be designed and configured to guarantee security by default, providing the minimum necessary functionality.
- Segregation of responsibilities: the roles of Security Officer and System Officer shall be kept separate.
5. Regulatory framework
The main regulations affecting this Policy are:
- Royal Decree 311/2022, of 3 May, regulating the National Security Framework (ENS).
- Directive (EU) 2022/2555 (NIS2), on measures for a high common level of cybersecurity across the Union.
- Regulation (EU) 2024/1689 (AI Act), laying down harmonised rules on artificial intelligence.
- Regulation (EU) 2024/2847 on horizontal cybersecurity requirements for products with digital elements (Cyber Resilience Act).
- Organic Law 3/2018, of 5 December, on Personal Data Protection and guarantee of digital rights.
- Regulation (EU) 2016/679 (GDPR), on the protection of natural persons with regard to the processing of personal data.
- Royal Decree 1007/2023 (Verifactu Regulation), on requirements for invoicing software systems.
- Law 18/2022 (Crea y Crece Act), regulating mandatory electronic invoicing between companies and self-employed professionals.
- Information security standards, in particular the latest versions of ISO/IEC 27001 and ISO/IEC 27002, as well as ISO/IEC 27034 (application security).
6. Security organization
Taking into account the articles set out in the ENS, the organization establishes the following actions to organize information security:
- It shall appoint security roles: Service Officer(s), Information Officer, Security Officer, System Officer and Data Protection Officer.
- It shall establish an advisory and strategic body for information security decision-making, called the Information Security Committee.
6.1. Information Officer (RINF) and Service Officer (RSERV)
- Establish the security requirements applicable to information and services, within the framework of Annex I of the ENS Royal Decree, and may request a proposal from the Security Officer, taking into account the System Officer’s opinion.
- Rule on access rights to information and services.
- Accept residual risk levels affecting information and services.
- Report to the Security Officer any change regarding the information and services under their responsibility, especially the addition of new services or information.
- Holds ultimate responsibility for the use made of certain services and information and therefore for their protection.
6.2. Security Officer (RSEG)
- Maintain and verify the appropriate level of security of the information handled and the services provided by the information systems.
- Promote information security training and awareness.
- Appoint those responsible for carrying out the risk analysis and the Statement of Applicability, identify security measures, determine required configurations and produce system documentation.
- Approve the Statement of Applicability based on the security measures required under Annex II of the ENS.
- Provide advice on determining the system category, in collaboration with the System Officer and the Security Committee.
- Take part in preparing and implementing security improvement plans and, where applicable, continuity plans, validating them.
- Manage external or internal system reviews and certification processes.
- Submit system changes and other requirements to the Security Committee for approval.
- Approve the security procedures forming part of the Regulatory Framework that fall outside the Committee’s remit, informing it of any changes made.
- Participate in drafting the Information Security Policy within the Committee, for approval by Management.
- Coordinate with the Secretary the calling of meetings, preparation of the agenda and drafting of minutes.
- Is responsible for the direct or delegated execution of the Committee’s decisions.
6.3. System Officer (RSIS)
- Develop, operate and maintain the information system throughout its lifecycle, producing the necessary operating procedures.
- Define the topology and management of the system, establishing usage criteria and available services.
- Halt access to information or provision of the service upon becoming aware of serious security deficiencies.
- Ensure that specific security measures are properly integrated into the overall security framework.
- Coordinate the functions of the system security administrator: management and updating of the hardware and software underpinning security mechanisms, and management of user authorizations and privileges, including activity monitoring.
- Approve changes to the current system configuration and ensure that approved controls and procedures are strictly followed.
- Supervise hardware and software installations, modifications and upgrades to ensure security is not compromised.
- Monitor security status using event management tools and technical audit mechanisms.
- Report any anomaly, compromise or vulnerability to the Security Officer and collaborate in investigating and resolving incidents.
6.4. Data Protection Officer (DPO)
- Inform and advise the organization and those carrying out processing of their obligations under data protection legislation.
- Monitor compliance with security regulations and internal data protection policies, including the assignment of responsibilities, staff awareness and training, and related audits.
- Provide advice on data protection impact assessments and monitor their implementation.
- Cooperate with the Spanish Data Protection Agency and act as its point of contact.
- Analyse and verify the compliance of processing activities, advise on data protection by design and by default, and prioritise activities on a risk basis.
6.5. Information Security Committee
The Committee is made up of a Chair, a Secretary and Members, classified as permanent or non-permanent depending on whether their participation is mandatory.
- Permanent members: Chair, Security Officer and System Officer.
- Non-permanent members: Service Officers, Information Officer, Data Protection Officer, organizational representatives or external specialists whose presence is advisable, and advisors (with a voice but no vote).
The Data Protection Officer participates with a voice but no vote when matters concerning personal data are addressed; if an item is put to a vote, their opinion shall always be recorded in the minutes. The Secretary issues the notices of meeting and takes the minutes.
Role composition: Chair, CEO. Secretary, Head of Operations & Alliances. Members: CEO, CFO, CTO, Head of Product Engineering, CPO and Head of Operations & Alliances. System Officer: Head of Product Engineering. Security Officer: CPO. Data Protection Officer: external provider (Govertis).
Main powers: regularly report the state of security to Senior Management; promote continuous improvement of the Information Security Management System; develop the evolution strategy; promote periodic audits; approve security documentation; stay informed of ENS conformity certification regulations and accredited certification bodies; coordinate efforts across areas; resolve conflicts of responsibility; and review the Information Security Policy prior to approval by the governing body.
Frequency: the Committee shall meet at least once a year, without prejudice to greater frequency should needs require. Meetings are called by the Chair through the Secretary, on their own initiative or by a majority of permanent members. Decisions are taken by consensus of the permanent members.
6.6. Appointment and conflict resolution
- The creation of the Committee, the appointment of its members and the designation of officers shall be carried out by means of an initial constitutive record.
- Roles are renewed automatically each year. Departures or changes shall be reported to the Committee, following the established channels for appointing the new officer.
- In accordance with Article 13.3 of the ENS Royal Decree, there may be no hierarchical dependency between the Security Officer and the System Officer, except in justified cases, which shall entail compensatory measures.
- Where a conflict arises between security requirements and operational or business needs, any officer may escalate it to the Committee, which shall decide by consensus, with the decision documented in the minutes.
- In situations of operational urgency where the Committee cannot be convened immediately, the Security Officer may adopt a provisional measure, documenting it and submitting it for ratification at the next session.
7. Personal data processing
AIRFLOWS processes personal data as described in the Record of Processing Activities. AIRFLOWS shall assess the risks relating to the personal data processed, proposing an action plan to correct any risks exceeding the authorised threshold.
The risk analysis shall be periodically reassessed, with the advice and supervision of the Data Protection Officer and, in any event, whenever high-risk processing is identified, carrying out an impact assessment where applicable. Implementation of the risk treatment plan shall be coordinated with that of the ENS, as shall other security procedures and standards with data protection obligations, especially in the oversight of service providers and the response to incidents and security breaches.
8. Risk management
All systems subject to this Policy shall carry out a risk analysis, assessing the threats and risks to which they are exposed. This analysis shall be repeated:
- Regularly, at least once a year.
- When there are changes in the information handled.
- When there are changes in the services provided.
- When a serious security incident occurs.
- When serious vulnerabilities are reported.
- When there are changes to the data protection risk analysis or impact assessments.
To harmonise risk analyses, the Security Committee shall establish a reference valuation for the different types of information handled and services provided, and shall facilitate the availability of resources to meet security needs, promoting horizontal investments. Data protection risks shall be taken into account, with the opinion of the Data Protection Officer, and risk treatment plans shall be coordinated.
The Statement of Applicability (SoA) sets out in detail the National Security Framework controls applicable to the information system of AIR FLOWS DATA PLATFORM, S.L., in accordance with Annex II of RD 311/2022, together with their applicability justification and maturity level.
9. Development of the Policy
This Policy shall be complemented by more specific documents — standards, security procedures and technical instructions — that help carry out what is proposed. The regulatory body is developed at three levels:
- First level: this Information Security Policy.
- Second level: the security standards derived from it, setting out the correct use of specific aspects of the management system.
- Third level: security procedures, guides and technical instructions determining the actions or tasks to be performed in carrying out a process.
Approval of the Information Security Policy rests with management, while the Security Committee is the body responsible for approving and disseminating the remaining documents, as established in Article 12 of the ENS Royal Decree. Any change must be communicated to all affected parties.
10. Staff obligations
All AIRFLOWS members are obliged to know and comply with this Policy and the standards, procedures or guides that develop it. It is AIRFLOWS’ responsibility, through the Security Committee and the people area, to provide the means necessary for this information to reach those concerned.
All AIRFLOWS members shall attend an information security awareness session at least once a year. A continuous awareness programme shall be established, particularly for new joiners.
Those responsible for the use, operation or administration of ICT systems shall receive training in the secure handling of systems to the extent needed to perform their work. Training is mandatory before assuming a responsibility, both on first appointment and on a change of position or responsibility.
11. Third parties
Where AIRFLOWS provides services to other entities or handles information belonging to others, they shall be made party to this Policy, without prejudice to data protection obligations where it acts as processor, and channels shall be established for reporting and coordination between the respective Security Committees and for incident response procedures. The Security Officer (or their delegate) shall be the Point of Contact (POC).
Where AIRFLOWS uses third-party services or transfers information to third parties, they shall be made party to this Policy and to the Security Regulations applying to those services or information. When contracting service providers or purchasing products, the successful bidder’s obligation to comply with the ENS shall be taken into account. When acquiring usage rights over cloud assets, the requirements of Annex II and the development guides shall be observed.
Such third parties shall be subject to the obligations set out in those regulations and may develop their own operating procedures to satisfy them, so that AIRFLOWS can supervise them or request evidence of compliance, including second- or third-party audits. Specific incident reporting and resolution procedures shall be established, channelled through the POC of the third parties involved and, where personal data is affected, through the Data Protection Officer. Third parties shall ensure their staff are adequately security-aware, at least to the level established in this Policy.
Where any aspect of the Policy cannot be met by a third party, the Security Officer shall issue a report specifying the risks incurred and how to address them. This report must be approved by the Information and Service Officers concerned before contracting begins or, where applicable, before award.
Where the organization acquires, develops or deploys an artificial intelligence system, in addition to complying with the applicable regulations it must obtain a report from the Security Officer, who shall consult the Information and Service Officers and, where necessary, the System Officer; the Data Protection Officer shall also give their opinion.
12. Security incident management
AIRFLOWS shall have a procedure for the agile management of security events and incidents that pose a threat to information and services.
This procedure shall be integrated with others relating to security incidents under other sectoral regulations — such as personal data protection — in order to coordinate the response across different approaches and to notify supervisory authorities without undue delay and, where necessary, State law enforcement agencies or the courts.
13. Approval and entry into force
This Information Security Policy shall be effective from its date of approval until replaced by a new Policy.
The Policy shall be reviewed by the Information Security Committee at planned intervals not exceeding one year, or whenever significant changes occur, in order to ensure its continued suitability, adequacy and effectiveness.
Text approved on 24 June 2026 by the Security Committee and the corresponding minutes of AIRFLOWS, by signature of minutes No. 002.